Connect to SAML Provider
In this topic, you will find instructions on how to establish a connection with an identity provider using the SAML protocol.
Prerequisites
Before you begin, ensure to have the following details from your IdP readily available:
- metadata URL (different IdPs may have different names for this)
- The assertion names for the following user information: first name, last name, username, email. For more information, see Map User Data.
This information can be obtained by reviewing the Digital.ai application instance configured in your IdP. If you have not already created an app instance for Digital.ai, you must do so before continuing. We recommend working with your IT team or whoever manages SSO administration at your company.
Log in to the Digital.ai Platform
- Log in to the Platform as an administrator.
- In the left navigation, under SSO, click Identity providers.
- Alternatively, you can click the Setup identity provider on the Platform overview page.
- Click Add identity provider button to open the identity provider configuration wizard.
Step 1: Select Provider Page
On the Select provider page, do the following:
- In Select authentication service, choose Add SAML Provider.
- In Select identity provider, choose the provider that your company uses. If your provider is not listed, choose Other.
- Under Configure your Identity provider, in Identity Provider display name, add a unique, user-friendly name for the IdP. This name will appear on the Digital.ai Platform login page.
- Click Next.
Step 2: Config identity provider and metadata Page
On the Config identity provider and metadata page, do the following:
-
Copy the Redirect URI and Service Provider Entity ID.
-
Now, in another browser window, you'll need to move over to your IdP account and use the Redirect URI and Service Provider Entity ID to identify the Digital.ai Platform as a valid redirect URL. The process for completing this task will differ depending on which IdP you use.
noteDepending on your role in your organization, you may need assistance from IT or whoever manages SSO administration at your company.
tipAfter you do this, you should be able to find the metadata URL if you hadn't already.
-
Select I have the metadata URL for my identity provider and paste the metadata URL into the Enter Metadata URL field.
- You can alternatively choose one of the other options here if it makes more sense for your situation.
-
Click Next.
Step 3: General Page
On the General page, do the following:
- In SAML configuration, enter the Single Sign-On Service URL.
- Click Next
Step 4: Advanced config Page
- Review the page and make any changes if necessary.
- Ensure that Sync Mode is set to
FORCE
. Sync Mode is set to FORCE by default, which allows Digital.ai to update a stored user's data whenever it is changed in the IdP. If you set it to IMPORT, user data is only imported the first time they log in through the IdP. - Click Next.
Step 5: Mappers Page
Mappers are required to ensure that the Platform correctly parses user information from your IdP. For more information and instructions on how to add mappers on this page, see Map User Data.
Step 6: Summary Page
- On the Summary page you can review the configuration details.
- Click Create identity provider.
A new button will now appear on the Digital.ai Platform login page with the name you added at the beginning of this procedure.